SC-900 Practice Question: Describe the capabilities of Microsoft security solutions
Exhibit
Refer to the exhibit.
```json
{
"permissions": [
{
"permission": "Sensitive Info Types"
},
{
"permission": "Data Classifiers"
},
{
"permission": "Content Explorer"
}
]
}
```Refer to the exhibit. A compliance administrator is configuring role-based access control (RBAC) in Microsoft Purview compliance portal. Which role group would provide the permissions shown?
⚠ Common exam trap
Test-takers frequently confuse the 'Compliance Administrator' role group with the 'Information Protection' role group, because both involve compliance tasks, but the exhibit specifically lists permissions that map to information protection functions, not broader compliance management.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Information Protection
The exhibit displays permissions related to managing sensitivity labels, label policies, and data loss prevention (DLP) rules within Microsoft Purview. The Information Protection role group is specifically designed for administrators who need to configure and manage these information protection features, making it the correct choice as it directly encompasses all the displayed permissions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Compliance Administrator
Why it's wrong here
The Compliance Administrator role group provides broad permissions for managing compliance features across Microsoft 365, including audit logs, eDiscovery, and data lifecycle management. However, it does not inherently grant the specific, granular permissions required to create, modify, or publish sensitivity labels and their associated policies, nor to configure auto-labeling rules. While powerful, it's not the most precise role for direct information protection configuration tasks.
- ✗
Security Reader
Why it's wrong here
The Security Reader role group is strictly limited to read-only access across various security and compliance features within Microsoft 365. This role allows administrators to view security reports, alerts, and configurations but explicitly prevents any write operations. Therefore, a user assigned to Security Reader cannot create new sensitivity labels, publish label policies, or configure automatic labeling rules, as these actions require modification permissions.
- ✗
Data Classification
Why it's wrong here
The term 'Data Classification' refers to a capability or a set of permissions related to identifying and categorizing data, rather than being a distinct, assignable role group within the Microsoft Purview compliance portal. While permissions for data classification exist, they are typically bundled within established role groups like 'Information Protection' or 'Compliance Administrator.' It is not a standalone role group that can be directly assigned to users.
- ✓
Information Protection
Why this is correct
The Information Protection role group is specifically designed to manage all aspects of sensitivity labels and related information protection features within the Microsoft Purview compliance portal. Members of this role group possess the necessary permissions to create, edit, publish, and delete sensitivity labels, configure label policies, and set up automatic labeling rules. This role provides the precise administrative capabilities required for comprehensive information protection management.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
Compliance Frameworks: ISO 27001, NIST, SOC 2
Key term
Labels
Labels are descriptive text or tags attached to IT resources to organize, identify, and manage them based on attributes like purpose, environment, or owner.
Key term
Group
A group is a collection of users, devices, or other objects that are assigned permissions and policies together for simplified management in identity and governance systems like Microsoft Entra ID.
About these practice questions
This SC-900 question is part of Courseiva's 1,279-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-900 exam.